The process of setting up secure LDAPS involves ‌importing the LDAP server's certificate into either the Java CACERTS truststore or your Windows certificates store.

TIP: For information about how to create a certificate for secure LDAP with Microsoft Entra Domain Services managed domain ('Azure Active Directory'), go to Tutorial: Configure secure LDAP for a Microsoft Entra Domain Services managed domain.

NOTE: The solution outlined here's applicable to all types of IRM installations. Depending on your wider system environment, alternative configurations may also be possible—for example, setting up a keystore to store the LDAP server certificate.

  1. If your LDAP connection:

    1. Is configured to use the currently authenticated Windows user account (that is, to Connect with active account):

      • Import the certificate of your LDAP server to your Windows certificates store.

    2. Is configured to store credentials through Storage - Local Machine or Storage - Local User (that is, not to Connect with active account):

      • Import the certificate of your LDAP server to the IRM JVM's CACERTS keystore, located in <Java install location>\lib\security\cacerts.

        For example (for Oracle Java), run the following command from the jre\bin folder of your Java deployment:
        keytool -import -trustcacerts -file ldap.crt -keystore ..\lib\security\cacerts -storepass changeit

        (In this example, ldap.crt is the name of the certificate and changeit is the default password.)
        NOTE: If you have multiple Java installations, ensure that you import it to the Java installation that's being used for IRM.

  2. In Library Manager, browse to \Trustees\Realm Settings\LDAP Setup\Connections, right-click and add a new connection.

    Type: Microsoft Active Directory 
    Server: <your server> 
    Port: 636 (or whatever the SSL port is for your server) 
    Use SSL = True

    The full username in the user field: 
    User: CN=My User,CN=Users,DC=YourDomain,DC=net 
    Password: <account password for user on LDAP server> 

When the connection is set up, importing of users and synchronization is the same.